Man arrested in Czech Republic, Yevgeniy Nikulin, indicted in US on charges related to hacking of LinkedIn, Dropbox, and Formspring in 2012
Context & Ripple Effects
Two days after LinkedIn publicly linked the arrested Russian to the 2012 breach that exposed 117M passwords, US prosecutors have formally indicted Yevgeniy Nikulin over the hacks of LinkedIn, Dropbox, and Formspring. The indictment converts corporate suspicion into criminal charges and sets up an extradition contest from Prague.
The case matters because it attaches a name to three of the defining credential breaches of 2012, and because the corpus shows the arc playing out over years: extradition to the US in 2018, conviction by a San Francisco jury in 2020, and ultimately a sentence of more than seven years.
First-order effects
- Yevgeniy Nikulin now faces US hacking charges for the 2012 LinkedIn, Dropbox, and Formspring breaches while in Czech custody, with Prague holding the extradition decision.
Second-order effects
- LinkedIn and Dropbox, already dealing with the fallout of roughly 117M stolen credentials, gain a prosecutorial handle on the breach — but the indictment also re-flags the exposure of years-old password data to users and regulators.
Third-order effects
- The multi-year path from indictment to a 7+ year sentence establishes that US prosecutors will pursue Russian nationals for decade-old mega-breaches through extradition, even when the defendant never sets foot on US soil voluntarily.
The trend: US prosecutors are increasingly closing the loop on years-old Russian-linked mega-breaches, using extradition as the lever to bring indicted hackers to trial.